Google Workspace connectors let each member of your organization link their own Gmail mailbox or Google Drive to Yellow, so the AI assistant and their private routines can read mail, send replies, search files, or save documents on their behalf. The connection is direct between Yellow and Google — no intermediary service — and it is strictly personal: each person connects their own account, and only their own chat and routines can use it.

Setting this up has two parts: a one-time authorization by your Google Workspace administrator, and then a per-person connection each member does in under a minute.

Part 1 — Authorize the app (Workspace administrator, once per domain)

Yellow's connectors use a dedicated Google application. Before anyone in your domain can connect an account, a Workspace administrator must mark that application as trusted:

  1. Open the Google Admin console with an administrator account.

  2. Go to Security → Access and data control → API controls → App access control.

  3. Click Manage third-party app access → Configure new app.

  4. Search by OAuth client ID and paste Yellow's connectors client ID:

    308291030853-n2c5d7ctrr71kskuont5j8e7h18dtm4d.apps.googleusercontent.com

  5. Select the app, choose the organizational units that may use it (or the whole domain), and set access to Trusted.

  6. Save. The change can take a few minutes to propagate.

Google may label the app as unverified during this process. That is expected: the app is distributed only to Workspace domains that explicitly trust it, which is Google's supported alternative to public verification. Marking it Trusted is precisely the step that authorizes it for your domain.

If this step is skipped, members will see an error like "admin_policy_enforced" or "access blocked" when they try to connect.

Part 2 — Connect your account (each member)

  1. In Yellow, open My connectors from the user menu.
  2. Click New connector, choose Catalog, and pick Gmail (Google Workspace) or Google Drive (Google Workspace). The name and tools come prefilled; create it.
  3. Open the connector's Credential tab and click Connect with Google.
  4. Your browser opens Google's consent screen. Sign in with your Workspace account (not a personal @gmail.com account) and accept.
  5. Back in Yellow, the tab shows Account connected. Use Test connection to confirm.

From that moment the connector's tools are available in your chat and — if you enable Available in workflows and routines — in your private routines. Nobody else in the organization can use your connection.

What each connector can do

Connector Tools
Gmail list and search messages, read a message, send a plain-text email
Google Drive search files, read a file (Docs are exported as text), save a new text file

The exact permissions requested from Google match these tools: Gmail read and send, Drive read plus files created by Yellow. Nothing else.

Disconnecting and revoking

  • Disconnect from Yellow: in the connector's Credential tab, choose Disconnect account. Yellow revokes its authorization at Google and deletes the stored credential.
  • Delete the connector: same effect, plus the connector disappears.
  • From Google: you can also revoke Yellow from your Google account permissions at any time; the connector then fails until you reconnect.
  • Domain-wide: the Workspace administrator can remove the app from the trusted list, which blocks new connections and invalidates existing ones.

Troubleshooting

  • "access blocked" / "admin_policy_enforced" when connecting — your Workspace administrator has not completed Part 1 yet, or your organizational unit is not included.
  • A personal @gmail.com account was used — these connectors require a Workspace account; sign in with your organization account instead.
  • Tools worked before but now fail asking to reconnect — the authorization was revoked or expired. Open the Credential tab and connect again.